
CVE disclosure for stored cross-site scripting (XSS) in SWISH Prolog up to v2.2.0, enabling arbitrary code execution and account takeover via crafted web IDE notebooks.
swish-prolog cve
Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook.
One click Account takeover.
Upgrade to the latest version to mitigate the ATO.
https://github.com/SWI-Prolog/swish/commit/4fb6acb97bedf993ec406a2ef324eeb2a16c49e3